Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-10536: curl may crash or be misused after reset
CVE-2026-10536 · published 3 months ago
Summary
The curl command‑line tool and its libraries can run into a problem when an application sets up certain HTTP/2 connections, then resets and finally closes them. This can cause the program to access memory that has already been released, potentially leading to a crash or allowing an attacker to take control. Update curl to the latest version to fix the issue.
What to do
- Update debian rootio-curl to version 7.88.1-10+deb12u15.aikido.13.
- Update alpine curl to version 8.14.1-r20071.
- Update alpine rootio-curl to version 8.14.1-r20071.
- Update bellsoft curl to version 8.21.0-r0.
- Update alpine curl to version 8.14.1-r20077.
- Update alpine curl to version 8.14.1-r20073.
- Update alpine rootio-curl to version 8.14.1-r20073.
- Update alpine rootio-curl to version 8.14.1-r20077.
- Update alpine curl to version 8.14.1-r20074.
- Update alpine rootio-curl to version 8.14.1-r20074.
- Update debian rootio-curl to version 8.14.1-2+deb13u4.aikido.14.
- Update debian curl to version 8.14.1-2+deb13u4.aikido.14.
- Update curl to version 8.14.1-r20079.
- Update rootio-curl to version 8.14.1-r20079.
- Update curl to version 8.14.1-2+deb13u5.aikido.18.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.18.
- Update curl to version 8.14.1-2+deb13u5.aikido.19.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.19.
- Update debian curl to version 8.21.0~rc2-1.
- Update curl to version 8.14.1-r30075.
- Update rootio-curl to version 8.14.1-r30075.
- Update curl to version 8.14.1-r200710.
- Update rootio-curl to version 8.14.1-r200710.
- Update curl to version 8.14.1-r20074.
- Update rootio-curl to version 8.14.1-r20074.
- Update curl to version 8.14.1-r30076.
- Update rootio-curl to version 8.14.1-r30076.
- Update curl to version 8.14.1-r200711.
- Update rootio-curl to version 8.14.1-r200711.
- Update curl to version 7.88.1-10+deb12u15.aikido.16.
- Update rootio-curl to version 7.88.1-10+deb12u15.aikido.16.
- Update curl to version 8.14.1-r30077.
- Update rootio-curl to version 8.14.1-r30077.
- Update curl to version 8.5.0-r00073.
- Update rootio-curl to version 8.5.0-r00073.
- Update curl to version 8.14.1-r20075.
- Update rootio-curl to version 8.14.1-r20075.
- Update curl to version 8.14.1-2+deb13u5.aikido.20.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.20.
- Update curl to version 8.14.1-r200712.
- Update rootio-curl to version 8.14.1-r200712.
- Update curl to version 8.14.1-r20076.
- Update rootio-curl to version 8.14.1-r20076.
- Update curl to version 8.5.0-r00074.
- Update rootio-curl to version 8.5.0-r00074.
- Update curl to version 8.14.1-r30079.
- Update rootio-curl to version 8.14.1-r30079.
- Update curl to version 8.14.1-2+deb13u5.aikido.21.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.21.
- Update curl to version 8.22.0-r0.
- Update curl to version 8.21.0-r0.
- Update curl to version 8.14.1-2+deb13u5.aikido.22.
- Update rootio-curl to version 8.14.1-2+deb13u5.aikido.22.
- Update curl to version 8.14.1-r20077.
- Update rootio-curl to version 8.14.1-r20077.
- Update curl to version 7.88.1-10+deb12u15.aikido.17.
- Update rootio-curl to version 7.88.1-10+deb12u15.aikido.17.
- Update haxx curl to version 8.21.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | curl | curl |
<= 8.20.0 < 8.14.2 < bfbff7852f050232edd3e5ca5c6bf2021c340f5a 8.20.0 |
| – | haxx | curl |
>= 7.88.0, < 8.21.0 cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* |
| Root:Debian:12 | debian | rootio-curl |
< 7.88.1-10+deb12u15.aikido.13 Fix: upgrade to 7.88.1-10+deb12u15.aikido.13
|
| Root:Alpine:3.22 | alpine | curl |
< 8.14.1-r20071 < 8.14.1-r20073 < 8.14.1-r20074 Fix: upgrade to 8.14.1-r20071
|
| Root:Alpine:3.22 | alpine | rootio-curl |
< 8.14.1-r20071 < 8.14.1-r20073 < 8.14.1-r20074 Fix: upgrade to 8.14.1-r20071
|
| Root:Alpine:3.21 | alpine | curl |
< 8.14.1-r20071 < 8.14.1-r20073 Fix: upgrade to 8.14.1-r20071
|
| Root:Alpine:3.21 | alpine | rootio-curl |
< 8.14.1-r20071 < 8.14.1-r20073 Fix: upgrade to 8.14.1-r20071
|
| BellSoft Hardened Containers:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.21.0-r0 Fix: upgrade to 8.21.0-r0
|
| Debian:11 | debian | curl | All versions |
| Debian:12 | debian | curl | All versions |
| Debian:13 | debian | curl | All versions |
| Debian:14 | debian | curl |
< 8.21.0~rc2-1 Fix: upgrade to 8.21.0~rc2-1
|
| Alpaquita:stream | bellsoft | curl |
>= 8.1.2-r0, < 8.21.0-r0 Fix: upgrade to 8.21.0-r0
|
| Root:Alpine:3.20 | alpine | curl |
< 8.14.1-r20077 Fix: upgrade to 8.14.1-r20077
|
| Root:Alpine:3.20 | alpine | rootio-curl |
< 8.14.1-r20077 Fix: upgrade to 8.14.1-r20077
|
| Root:Debian:13 | debian | rootio-curl |
< 8.14.1-2+deb13u4.aikido.14 Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
|
| Root:Debian:13 | debian | curl |
< 8.14.1-2+deb13u4.aikido.14 Fix: upgrade to 8.14.1-2+deb13u4.aikido.14
|
| Root:Alpine:3.20 | – | curl |
< 8.14.1-r20079 < 8.14.1-r200710 < 8.14.1-r200711 < 8.14.1-r200712 Fix: upgrade to 8.14.1-r20079
|
| Root:Alpine:3.20 | – | rootio-curl |
< 8.14.1-r20079 < 8.14.1-r200710 < 8.14.1-r200711 < 8.14.1-r200712 Fix: upgrade to 8.14.1-r20079
|
| Root:Debian:13 | – | curl |
< 8.14.1-2+deb13u5.aikido.18 < 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 < 8.14.1-2+deb13u5.aikido.21 < 8.14.1-2+deb13u5.aikido.22 Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
|
| Root:Debian:13 | – | rootio-curl |
< 8.14.1-2+deb13u5.aikido.18 < 8.14.1-2+deb13u5.aikido.19 < 8.14.1-2+deb13u5.aikido.20 < 8.14.1-2+deb13u5.aikido.21 < 8.14.1-2+deb13u5.aikido.22 Fix: upgrade to 8.14.1-2+deb13u5.aikido.18
|
| Root:Alpine:3.22 | – | curl |
< 8.14.1-r30075 < 8.14.1-r30076 < 8.14.1-r30077 < 8.14.1-r30079 Fix: upgrade to 8.14.1-r30075
|
| Root:Alpine:3.22 | – | rootio-curl |
< 8.14.1-r30075 < 8.14.1-r30076 < 8.14.1-r30077 < 8.14.1-r30079 Fix: upgrade to 8.14.1-r30075
|
| Root:Alpine:3.21 | – | curl |
< 8.14.1-r20074 < 8.14.1-r20075 < 8.14.1-r20076 < 8.14.1-r20077 Fix: upgrade to 8.14.1-r20074
|
| Root:Alpine:3.21 | – | rootio-curl |
< 8.14.1-r20074 < 8.14.1-r20075 < 8.14.1-r20076 < 8.14.1-r20077 Fix: upgrade to 8.14.1-r20074
|
| Root:Debian:12 | – | curl |
< 7.88.1-10+deb12u15.aikido.16 < 7.88.1-10+deb12u15.aikido.17 Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
|
| Root:Debian:12 | – | rootio-curl |
< 7.88.1-10+deb12u15.aikido.16 < 7.88.1-10+deb12u15.aikido.17 Fix: upgrade to 7.88.1-10+deb12u15.aikido.16
|
| Root:Alpine:3.15 | – | curl |
< 8.5.0-r00073 < 8.5.0-r00074 Fix: upgrade to 8.5.0-r00073
|
| Root:Alpine:3.15 | – | rootio-curl |
< 8.5.0-r00073 < 8.5.0-r00074 Fix: upgrade to 8.5.0-r00073
|
| Alpine:v3.23 | – | curl |
>= 7.88.0, < 8.22.0-r0 Fix: upgrade to 8.22.0-r0
|
| Alpine:v3.24 | – | curl |
>= 7.88.0, < 8.21.0-r0 Fix: upgrade to 8.21.0-r0
|
Original advisory text
CVE-2026-10536 in curl - Patched by Root
A use-after-free vulnerability exists in libcurl when an application
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and
finally terminates the handle with `curl_easy_cleanup()`. During this final
cleanup phase, libcurl attempts to access and modify an internal structure
that was already freed during the reset operation.
configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or
`CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and
finally terminates the handle with `curl_easy_cleanup()`. During this final
cleanup phase, libcurl attempts to access and modify an internal structure
that was already freed during the reset operation.
References
- https://security-tracker.debian.org/tracker/CVE-2026-10536 Vendor Advisory
- https://curl.se/docs/CVE-2026-10536.json Vendor Advisory
- https://github.com/curl/curl.git Product
- https://docs.bell-sw.com/security/cves/CVE-2026-10536 Vendor Advisory
- https://curl.se/docs/CVE-2026-10536.html Patch Vendor Advisory
- https://hackerone.com/reports/3751697 Exploit Issue Tracking Third Party Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10536... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-10536 Vendor Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-10536 Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-416Use After Free
Timeline
Published3 Jul 2026
Updated9 Oct 2026
First seen24 Jun 2026
Sources
CVE-2026-10536 · OSV
CURL-CVE-2026-10536 · OSV
CVE-2026-10536 · NVD
CVE-2026-10536 · MITRE
BELL-CVE-2026-10536 · OSV
DEBIAN-CVE-2026-10536 · OSV
ALPINE-CVE-2026-10536 · OSV
Track software like this
Free during beta